Observed Signal · Jun 1, 2026 · Security Vulnerability · Source: DEV Community · Impact: 4/5 · Sentiment: Negative

Deleted Google API Keys Remain Active for 23 Minutes

Executive Signal Summary

A security researcher (Joe Leon) found that deleting a Google API key does not immediately invalidate it: due to eventual consistency and cached credential state across Google Cloud's distributed authentication layer, revoked keys can remain valid for up to 23 minutes. Google initially called this expected behavior but later reclassified the issue as a critical P0/S0 bug after public disclosure. The problem is amplified because Google reused the same API key infrastructure for Gemini (LLM) as for lower-risk services like Maps, increasing the blast radius of leaked keys. The article explains implications for incident response, compares propagation/invalidations for AWS and Postmark, and recommends stricter key restrictions, backend proxies for sensitive APIs, credential rotation, explicit session invalidation, billing alerts, and enhanced monitoring after key deletion.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

A major platform (Google) exposed an operational security gap that breaks common incident‑response assumptions, increases risk for LLM/billing/data exposure, and requires immediate operational changes for cloud credential handling.

SIGNAL RADAR

Track Google Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • Security researcher Joe Leon reported that deleting a Google API key does not immediately stop its use; revoked keys can remain valid for up to 23 minutes.
  • Google initially classified the behavior as expected but later reclassified it as a critical P0/S0 bug after public disclosure.
  • Google reused its existing API key infrastructure for Gemini (its LLM), increasing the potential impact of leaked keys compared with traditional Maps keys.
  • AWS IAM key deletions generally propagate quickly, but STS-derived temporary credentials remain valid until they expire; Postmark tokens can be invalidated immediately.
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: DEV Community•Published: Jun 1, 2026
Original Coverage Title: “Your Deleted Google API Key Is Still Working — Here's Why That's a Security Crisis”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

Large Language Models (LLM) & AIApr 11, 2026

Leaked Google API keys lead to $82k Gemini bill

A security analysis by Truffle Security found nearly 3,000 Google API keys publicly exposed online. Because Google uses a single API-key format that both identifies a cloud project and grants authorization, enabling the Gemini AI API on an existing project can allow that same key to be used for costly Gemini calls without an explicit user prompt. A small Mexican developer team reported a spike from a typical $180 monthly bill to a charge of $82,314.44 for February 2026 after their key was abused; Google reportedly is holding to the invoice. Truffle Security also found old public keys that could access internal Google Gemini systems. Google has since begun automatically blocking leaked keys and — according to reporting — will proactively notify customers about publicly accessible API keys.

Read assessment
Productivity & Collaboration SaaSApr 4, 2026

Google Drive Links Never Expire — Security Risk

The article explains that Google Drive links shared using the "anyone with the link can view" setting do not expire by default, leaving files accessible indefinitely unless manually revoked. This creates a common security and compliance exposure for organizations, agencies, contractors and former employees who may retain access via old links. Citing industry research, the author notes the average company has thousands of externally shared Workspace files and that very few organizations audit or revoke such access routinely. The piece urges improvements — automatic link expiration, centralized access auditing and offboarding integration — and recommends immediate mitigations (quarterly audits, avoid public links, add revoke steps to offboarding). It also highlights regulatory risk (GDPR, SOC 2) when sensitive or regulated data remains accessible via stale links.

Read assessment
Data breachMay 6, 2026

Braintrust Confirms Breach, Urges Customers to Rotate API Keys

Braintrust, an AI-evaluation startup, confirmed unauthorized access to one of its Amazon Web Services (AWS) cloud accounts that stored customer API keys and sensitive secrets. The company told customers to revoke and rotate any API keys stored with Braintrust, said it contained the incident, locked down the compromised account, audited and restricted related access, and rotated internal secrets. Braintrust said the cause is under investigation and that it has not found evidence of broader exposure to date. A Braintrust spokesperson characterized the notification as precautionary. The incident raises potential downstream risks for customers that rely on keys stored with third-party cloud services.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.